漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
N/A
Vulnerability Description
private_address_check ruby gem before 0.5.0 is vulnerable to a time-of-check time-of-use (TOCTOU) race condition due to the address the socket uses not being checked. DNS entries with a TTL of 0 can trigger this case where the initial resolution is a public address but the subsequent resolution is a private address.
CVSS Information
N/A
Vulnerability Type
使用共享资源的并发执行不恰当同步问题(竞争条件)
Vulnerability Title
private_address_check ruby gem 竞争条件漏洞
Vulnerability Description
private_address_check ruby gem是一款基于Ruby的服务器端请求伪造攻击检查工具。 private_address_check ruby gem 0.5.0之前版本中存在竞争条件漏洞,该漏洞源于程序没有检测套接字所使用的地址。攻击者可通过发送特制的请求利用该漏洞造成应用程序崩溃。
CVSS Information
N/A
Vulnerability Type
N/A